"Express Mail" No. 




;634266US 




I Patent Application 

Ittorney Docket No. D/99164 



SYSTEM AND METHOD FOR DOCUMENT DISTRIBUTION 



5 CROSS-REFERENCE TO RELATED APPLICATION 

This application claims the benefit of U.S. Provisional Application No. 
60/128,164, filed on April 6, 1999. 

10 FIELD OF THE INVENTION 

The invention relates to cryptographic methods, and more particularly to systems 
and methods for efficiently distributing encrypted documents to a large number of 
recipients. 



BACKGROUND OF THE INVENTION 

One of the most important issues impeding the widespread distribution of digital 
documents via electronic commerce is the current lack of protection of the intellectual 

20 property rights of content owners during the distribution and use of those digital 
documents. Efforts to resolve this problem have been termed "Intellectual Property 
Rights Management" ("IPRM"), "Digital Property Rights Management" ("DPRM"), 
"Intellectual Property Management" ("IPM"), "Rights Management" ("RM"), and 
"Electronic Copyright Management" ("ECM"). 

25 A document, as the term is used herein, is any unit of information subject to 

distribution or transfer, including but not limited to correspondence, books, magazines, 
journals, newspapers, other papers, software, photographs and other images, audio and 
video clips, and other multimedia presentations. A document may be embodied in 
printed form on paper, as digital data on a storage medium, or in any other known manner 

30 on a variety of media. 
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In the world of printed documents, a work created by an author is usually 
provided to a publisher, which formats and prints numerous copies of the work. The 
copies are then sent by a distributor to bookstores or other retail outlets, from which the 
copies are purchased by end users. 

5 While the low quality of copying and the high cost of distributing printed material 

have served as deterrents to the illegally copying of most printed documents, it is far too 
easy to copy, modify, and redistribute unprotected electronic documents. Accordingly, 
some method of protecting electronic documents is necessary to make it harder to 
illegally copy them. This will serve as a deterrent to copying, even if it is still possible, 

10 for example, to make hardcopies of printed documents and duplicate them the old- 
fashioned way. 

With printed documents, there is an additional step of digitizing the document 
before it can be redistributed electronically; this serves as a deterrent. Unfortunately, it 
has been widely recognized that there is no viable way to prevent people from making 

15 unauthorized distributions of electronic documents within current general-purpose 
computing and communications systems such as personal computers, workstations, and 
other devices connected over local area networks (LANs), intranets, and the Internet. 
Many attempts to provide hardware-based solutions to prevent unauthorized copying 
have proven to be unsuccessful. 

20 Two basic schemes have been employed to attempt to solve the document 

protection problem: secure containers and trusted systems. 

A "secure container" (or simply an encrypted document) offers a way to keep 
document contents encrypted until a set of authorization conditions are met and some 
copyright terms are honored (e.g., payment for use). After the various conditions and 

25 terms are verified with the document provider, the document is released to the user in 
clear form. Commercial products such as IBM's Cryptolopes and InterTrust's Digiboxes 
fall into this category. Clearly, the secure container approach provides a solution to 
protecting the document during delivery over insecure channels, but does not provide any 
mechanism to prevent legitimate users from obtaining the clear document and then using 

30 and redistributing it in violation of content owners' intellectual property. 
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Cryptographic mechanisms are typically used to encrypt (or "encipher") 
documents that are then distributed and stored publicly, and ultimately privately 
deciphered by authorized users. This provides a basic form of protection during 
document delivery from a document distributor to an intended user over a public 

5 network, as well as during document storage on an insecure medium. 

In the "trusted system" approach, the entire system is responsible for preventing 
unauthorized use and distribution of the document. Building a trusted system usually 
entails introducing new hardware such as a secure processor, secure storage and secure 
rendering devices. This also requires that all software applications that run on trusted 

10 systems be certified to be trusted. While building tamper-proof trusted systems is still a 
real challenge to existing technologies, current market trends suggest that open and 
untrusted systems such as PC's and workstations will be the dominant systems used to 
access copyrighted documents. In this sense, existing computing environments such as 
PC s and workstations equipped with popular operating systems (e.g., Windows and 

15 UNIX) and render applications (e.g., Microsoft Word) are not trusted systems and cannot 
be made trusted without significantly altering their architectures. 

Accordingly, although certain trusted components can be deployed, one must 
continue to rely upon various unknown and untrusted elements and systems. On such 
systems, even if they are expected to be secure, unanticipated bugs and weaknesses are 

20 frequently found and exploited. 

One particular issue arises in the context of document distribution, as described 
generally above. In the traditional model of document distribution, the content author 
and the publisher typically do not handle distribution; a separate party with distribution 
expertise is given that responsibility. Furthermore, while it is possible to encrypt a 

25 document (using standard techniques) so that multiple recipients can decrypt it, it is not 
usually known at the time a work is created who the ultimate users will be. It makes 
more sense for the distributor to determine who the end users will be, and to distribute the 
document to them as desired. If, as in traditional model, the original work of authorship 
is sent to a publisher and a distributor in the clear, that is a point of vulnerability for the 

30 work. 
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A similar problem arises in office settings, for example, in which it is frequently 
desirable to designate what is variously called a document agent, surrogate, or delegate. 
In this situation, it is often useful to be able to give an administrative assistant or 
secretary the right to decrypt certain document not intended directly for that person. 

5 Considering the problem more broadly, in a networked environment, messages 

are often passed to recipients other than their initially intended ones. When message 
confidentiality is a concern and encrypted messages are forwarded, it is very desirable to 
allow one to decrypt these messages on behalf of another. To be concrete, suppose that 
Bob is the one who needs to read some message that is initially encrypted for Alice. One 

10 trivial solution is that Alice simply reveals her decryption key to Bob so that Bob can use 
it to decrypt the message himself. This requires Alice to trust Bob totally, which may not 
be acceptable to Alice. Another way to accomplish this task is to let Alice first decrypt 
the message, then re-encrypt it for Bob and finally send the newly encrypted message to 
Bob so that he can decrypt. Though the message is communicated securely, this solution 

15 is less efficient as it requires two decryption and one encryption operations in order for 
Bob to obtain the message. More importantly, in some situations such re-encryption 
solution is not even applicable or desirable. For example, Alice may not have access to 
the encrypted message, as it may be sent by its originator directly to Bob for 
communication efficiency and other considerations. Also, decrypting the encrypted 

20 message to a clear version, even if only for a short time, can be a substantial 
vulnerability. 

Accordingly, it would be desirable to have an encryption/decryption framework 
that supports the ability to transfer the right to decode messages. Such a framework 
would allow a delegate to, essentially, authorize the re-encryption of a message for 
25 another party's use without first decrypting the original message. It would also be useful 
for this to be possible without the delegate ever having possession of the encrypted 
message. 
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SUMMARY OF THE INVENTION 

How to transfer the right to decrypt from one key holder to another in a secure 
and efficient way is the subject of proxy encryption. Some specific proxy encryption 
5 schemes have been recently proposed to convert messages encrypted for one key into 
messages encrypted for another without revealing secret decryption keys and original 
messages to the public. Mambo and Okamoto have introduced several private, non- 
commutative, message-independent proxy encryption schemes. Blaze and Strauss have 
introduced a public, commutative, message-independent proxy encryption scheme. 

10 In this disclosure, the same general problem is initially addressed but in the more 

general context of encoding schemes. Encoding schemes considered in this disclosure 
differ from encryption schemes or cryptosystems in that they do not necessarily have any 
security-related requirements. For an encoding scheme to be an encryption scheme, it is 
necessary that an eavesdropper, upon seeing an encoded message, should be unable to 

15 determine either the original message or the key used to decode the message. Working 
with encoding schemes makes it possible to build applications with lightweight security 
but high implementation efficiency, such as efficient massive document distribution and 
updating of ciphertext with new keys to protect long-term encrypted messages. In this 
disclosure, a class of encoding schemes is defined, and several example schemes are 

20 given. A process by which new schemes can be constructed using existing ones is also 
offered herein. 

Several more formal proxy encryption schemes are then presented. A proxy 
encryption scheme is an encryption scheme that allows a designated key holder to 
decrypt messages on behalf of another key holder. This disclosure introduces two new 

25 proxy encryption schemes based on the known ElGamal scheme, with improved 
functionalities over existing proxy encryption schemes. They are public in the sense that 
proxy-related information and transformations can be safely made to the public, and at 
the same time non-commutative in terms of trust relationships among involved key 
holders. Applications of these new schemes to massive document distribution and file 

30 protection are also presented. 
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The basic idea in the methods present in this disclosure is as follows: in order for 
Alice to transfer the right to decode to Bob, Alice generates a transfer key t for Bob. 
With the transfer key f, Bob can re-encrypt the message initially encoded for Alice and 
subsequently decrypt it using his own key. Much like in proxy encryption, the transfer is 

5 performed in such a way that the transfer key does not explicitly reveal the decoding keys 
of either Alice or Bob, or the original message. 

How to delegate the right to decrypt from one key holder to another in secure and 
efficient ways is the subject of proxy encryption. Very recently, some specific proxy 
encryption schemes have been proposed to convert messages encrypted for one key into 

10 messages encrypted for another without revealing secret decryption keys and original 
messages to the public. Mambo and Okamoto have described three proxy encryption 
schemes for the ElGamal and RSA encryption schemes. M. Mambo and E. Okamoto, 
"Proxy cryptosy stems: Delegation of the power to decrypt ciphertexts," IEICE Trans, on 
Fundamentals, Vol. E80-A, No. 1, pp. 54-63 (1997). For the situation mentioned 

15 above, their schemes have better computational performance over the re-encryption 
scheme, but for security reasons require the presence of the original key holder Alice in 
the message conversion. Moreover, the schemes themselves do not help specifying who 
is the key holder that Alice wants to delegate the decryption right to. The scheme 
proposed by Blaze and Strauss, on the other hand, does not have these shortcomings. It is 

20 a modification of the ElGamal encryption scheme. M. Blaze and M. Strauss, "Proxy 
Cryptography," Draft, AT&T Research Labs, ftp://ftp.research.att.com/dist/mab/proxy.ps 
(May 1997). One very appearing feature of the Blaze and Strauss scheme is that it 
permits communicating proxy related information and performing the message 
conversion in public. But it introduces a more serious problem: it is commutative in the 

25 sense that Bob is able to obtain Alice's decryption key. This type of commutativity 
makes the proxy encryption scheme obsolete, as the entire scheme can be well simplified 
to giving Alice's key to Bob and letting Bob decrypt. Another issue (not necessarily a 
problem) created by this scheme is that once Bob has been granted the decryption right 
by Alice, he can decrypt all messages that are originally for Alice. This message- 

30 independence may be useful in some cases such as self-delegation but is not be desirable 
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in many practical applications where the original key holder wants to be selective on 
which messages the delegated decryption is allowed. 

Accordingly, the proxy encryption schemes according to the present invention, 
which are public and non-commutative, eliminate some of the disadvantages of other 
5 known cryptosy stems. 

In this disclosure, two new proxy encryption schemes are then introduced. They 
are all based on the ElGamal public-key encryption scheme and have comparable 
computational performance. Essentially, they have retained the following desirable 
features of the existing schemes: (i) public: the presence of the original key holder is not 
10 required after proxy information is generated, and proxy related information and 
operations can communicated and conducted in public; (ii) non-commutative: key holders 
do not have to trust each other in regard to their private decryption keys; and (iii) 
restricted: the key holder to whom the decryption right is delegated to is specified, and 
the proxy information (key) is message dependent. 
15 Finally, delegating the right to decrypt messages is then described in the context 

of the Cramer-Shoup cryptosystem, which bears some advantages over other systems. 

These and other features and advantages of the present invention are apparent 
from the Figures as fully described in the Detailed Description of the Invention. 

20 BRIEF DESCRIPTION OF THE DRAWINGS 

FIGURE 1 is a block diagram of an electronic document distribution system 
capable of operation according to the invention; 

FIGURE 2 is a block diagram illustrating the encoding operations performed 
25 when delegating the authority to decrypt a message in a method according to the 
invention; 

FIGURE 3 is a flow chart illustrating the general steps performed in transforming 
an encoded message for decoding by another; 

FIGURE 4 is a block diagram schematically illustrating the parties involved in a 
30 system adapted for the delegation of the authority to decrypt messages; 
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FIGURE 5 is a flow chart illustrating the steps performed in a generic proxy 
encryption scheme; 

FIGURE 6 is a flow chart illustrating the steps performed in encrypting and 
decrypting a message according to the ElGamal cryptosystem; 
5 FIGURE 7 is a flow chart illustrating the steps performed in a known ElGamal- 

based proxy encryption and decryption scheme proposed by Mambo and Okamoto; 

FIGURE 8 is a flow chart illustrating the steps performed in a known ElGamal- 
based proxy encryption and decryption scheme proposed by Blaze and Strauss; 

FIGURE 9 is a flow chart illustrating the steps performed in a first embodiment of 
10 an ElGamal-based proxy encryption and decryption scheme according to the invention; 

FIGURE 10 is a flow chart illustrating the steps performed in a second 
embodiment of an ElGamal-based proxy encryption and decryption scheme according to 
the invention; 

FIGURE 11 is a flow chart illustrating the steps performed in a document 
15 distribution scheme according to the invention; 

FIGURE 12 is a flow chart illustrating the steps performed in a file protection 
scheme according to the invention; 

FIGURE 13 is a flow chart illustrating the steps performed in encrypting and 
decrypting a message according to the Cramer-Shoup cryptosystem; and 
20 FIGURE 14 is a flow chart illustrating the steps performed in an embodiment of a 

Cramer-Shoup-based proxy encryption and decryption scheme according to the 
invention. 

The Figures are more fully explained in the following Detailed Description of the 
Invention. 

25 

DETAILED DESCRIPTION OF THE INVENTION 

The invention is described below, with reference to detailed illustrative 
embodiments. It will be apparent that the invention can be embodied in a wide variety of 
30 forms, some of which may be quite different from those of the disclosed embodiments. 
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Consequently, the specific structural and functional details disclosed herein are merely 
representative and do not limit the scope of the invention. 

Figure 1 represents a top-level functional model for a system for the electronic 
distribution of documents, which as defined above, may include correspondence, books, 

5 magazines, journals, newspapers, other papers, software, audio and video clips, and other 
multimedia presentations. 

An author (or publisher) 1 10 creates a document's original content 1 12 and passes 
it to a distributor 114 for distribution. Although it is contemplated that the author may 
also distribute documents directly, without involving another party as a publisher, the 

10 division of labor set forth in Figure 1 is more efficient, as it allows the author/publisher 
110 to concentrate on content creation, and not the mechanical and mundane functions 
taken over by the distributor 114. Moreover, such a breakdown would allow the 
distributor 1 14 to realize economies of scale by associating with a number of authors and 
publishers (including the illustrated author/publisher 110). 

15 The distributor 114 then passes modified content 116 to a user 118. In a typical 

electronic distribution model, the modified content 116 represents an re-encrypted 
version of the original encrypted content 112; the distributor 114 first decrypts the 
original content 112 and then re-encrypts it with the user 1 18's public key; that modified 
content 1 16 is customized solely for the single user 118. The user 1 18 is then able to use 

20 his private key to decrypt the modified content 116 and view the original content 112. 

A payment 120 for the content 112 is passed from the user 118 to the distributor 
114 by way of a clearinghouse 122. The clearinghouse 122 collects requests from the 
user 118 and from other users who wish to view a particular document. The 
clearinghouse 122 also collects payment information, such as debit transactions, credit 

25 card transactions, or other known electronic payment schemes, and forwards the collected 
users' payments as a payment batch 124 to the distributor 114. Of course, it is expected 
that the clearinghouse 122 will retain a share of the user's payment 120. In turn, the 
distributor 114 retains a portion of the payment batch 124 and forwards a payment 126 
(including royalties) to the author and publisher 110. In one embodiment of this scheme, 

30 the distributor 114 awaits a bundle of user requests for a single document before sending 
anything out. When this is done, a single document with modified content 116 can be 
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generated for decryption by all of the requesting users. This technique is well-known in 
the art. 

In the meantime, each time the user 118 requests (or uses) a document, an 
accounting message 128 is sent to an audit server 130. The audit server 130 ensures that 
5 each request by the user 118 matches with a document sent by the distributor 114; 
accounting information 131 is received by the audit server 130 directly from the 
distributor 1 14. Any inconsistencies are transmitted via a report 132 to the clearinghouse 
122, which can then adjust the payment batches 124 made to the distributor 114. This 
accounting scheme is present to reduce the possibility of fraud in this electronic 
10 document distribution model, as well as to handle any time-dependent usage permissions 
that may result in charges that vary, depending on the duration or other extent of use. 

The foregoing model for electronic commerce in documents, shown in Figure 1, is 
in common use today. As will be shown in detail below, it is equally applicable to the 
system and method set forth herein for the distribution of self-protecting documents. 



Proxy Encoding Schemes 

For simplicity, initially consider encoding schemes of the following type. An 
encoding system consists of four components: (i) a message space X which is a collection 
20 of possible messages, (ii) a key space K which is a set of possible keys, (iii) a 
computationally efficient encoding transformation E.KxX— >X and (iv) a 
computationally efficient decoding transformation D : KxX ^> X . For each k e K , the 
encoding transformation E k : X -» X and decoding transformation D k : X — » X are 
injection (one-to-one) mappings on X, and they satisfy that, for every message jce X , 



Certainly, such defined encoding schemes can be varied in several ways to cover a wider 
range of ones. One is to differentiate the space of encoded messages from the one of 
original messages, and another is to consider that keys used for encoding and decoding 
are different. In terms of cryptography, the encoding schemes considered below are 
30 essentially private-key (or, more precisely, symmetric), endomorphic cryptosystems. 



15 



25 



D k {E k {x)) = x. 
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Such defined encoding schemes have some advantageous properties. Given an 
encoding scheme (X, K 9 E, D) y each encoding transformation and its corresponding 
decoding transformation are inverse transformation of each other; that is, for each k e K , 

D t and£ t =(D t )-'. 

5 If X is a finite set, each encoding or decoding transformation is just a permutation on X. 

Classic, symmetric-key encryption schemes are encoding schemes. Here are 
some of them. 

XOR Scheme X. In this scheme, the message space X is the set B„ of all n-bit 
binary strings for some integer n > 0, and so is the key space K. The number of possible 
10 messages and the number of possible keys are both 2". For each message x and each key 
k, the encoding is 

y = E k (x) = x © k 

and the decoding of message y is 

x = D k (y) = y®k\ 
15 where © represents the bit-wise XOR (exclusive or) operation. 

Multiplicative Scheme Af. A message in this scheme is an element in 
X = Z n = {0, 1, . . ., n-1 } for some integer n > 0. A key is also an element a in Z„ but 
satisfying gcd(a, n) = 1, where the "gcd" function specifies the greatest common integer 
divisor of the two arguments. That is, the key space K consists of the elements in the 
20 multiplicative group Z* = {a e Z n I gcd(a,n) = 1} . The encoding of a message x with a 
key a is 

y = E a (x) = ax(modn) 
and the decoding of a message y with a key a is 

x = D a (y) = a~ x y(modn) J 

25 where a' 1 is the multiplicative inverse of a modulo n; that is, a 1 is an element in Z n such 
that aa _1 (niod n) = a _1 a(mod n) = 1. Note that the condition on a, gcd(a, n) = 1, is used to 
guarantee that a has the inverse a 1 . It is known that the number of such as is equal to the 
value of the Euler phi-function 

m 

<i>(n)=Y[<<p?-pr x ) 



ii 



where 

n = flp? 

i-l 

is the prime decomposition of n. So the number of keys in the scheme M is <j>{n) . 

Shift Scheme S. Messages and keys of the shift scheme are all elements in 
5 Z n = {0, 1, n-1} for some integer n>0; that is, X = K=Z n . Thus, the number of 
messages and the number of keys in the shift scheme are all equal to n. To encode a 
message x with a key b, one calculates 

y ~ Eb(x) - x + b (mod n) 
and to decode a message y with b, one computes 
10 x- D b (y) = y-b (mod n) . 

Substitution Scheme P. This scheme is also defined over X = Z*. However, the 
key space K~Yl n consists of all permutations of elements in Z„. Thus, the total number 
of keys is n!. For each permutation p e II n , the encoding is 

y = E p (x)=p(x\ 

15 while the decoding is 

where p~ l is the inverse permutation of p. 

It should be noted that the multiplicative and shift schemes are special cases of the 
substitution scheme which include only <j)(ri) and « of the n! possible permutations of n 

20 elements, respectively. 

New encoding schemes can be constructed by combining existing ones. One way 
is to form their "product." Suppose S and 5" are two encoding schemes with the same 
message space X. The product of S and S\ denoted by SxS\ has the same message 
space X. A key of the product scheme has the form (fc, A:'), where k and k' are keys of S 

25 and S\ respectively. The encoding and decoding transformations of the product 
scheme are defined as follows: for each key {kX) e K , 

and 

D ikX) {x) = D k {D',{c)). 
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That is, the message jc is first encoded with and the resulting message is then "re- 
encoded" with Ek'. Decoding is similar, but it is done in the reverse order. 

It is straightforward to check that the product construction is always associative: 
(SxS')xS* = Sx(S'xS'). Ifan encoding scheme 5 is taken to form the product 
5 with itself, one obtains the scheme SxS , denoted by S 2 . If the w-fold product is taken, 
the resulting scheme, denoted by S", is called an iterated encoding scheme. 

A simple example to illustrate the definition of product encoding schemes is as 
follows. 

Affine Scheme A. This scheme is also defined over X = Z n . A key of the affine 
10 scheme is a pair of integers (a, b) in Z„, where gcd(a, n)=l. The encoding 
transformation is 

y - E{a y b)(x) = (ax + b) (mod n) 
and the decoding transformation is 

x = D (flj b) (y) = a l (y - b) (mod n) 

15 where a 1 is the modular inverse of a modulo n. These transformations of the type ax + b 
are usually called affine transformations, hence the name affine scheme. Note that the 
scheme A reduces to the multiplicative scheme M when b = 0 and the shift scheme 5 
when a - I. Thus, M and S are special cases of A. On the other hand, A is their product 
MxS . As seen before, a key in the multiplicative scheme M is an element aeZ* n ; the 

20 corresponding encoding transformation is E a (x) = ax (mod n). A key in the shift scheme 
is an element beZ n , and the corresponding encoding transformation is 
Eb{x) = x + b (mod n). Hence, a key in the product scheme MxS has the form 
(a,b) e Z* x Z n , and its encoding is 

E{a y b)(x) = E b (E a (x)) = ax + b (mod n) . 
25 This is precisely the definition of the encoding transformation in the affine scheme. 
Similarly, the decoding transformation in the affine scheme is the composition of the 
decoding transformations of the shift and multiplicative schemes. 

The objective of transferring the right to decode messages in any given encoding 
scheme (X,K,E,D) can be stated as follows: for any given message xe X and keys 
30 k,k'e K , convert in some efficient way the encoded message y = £*(jc) using the key k 
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into the encoded message / = using the key k 1 so that the new message / can be 
decoded correctly using the key k\ If this can be achieved, it is said that the right to 
decode the message y has been transferred or delegated from the key holder of k to the 
key holder of k\ 

5 Figure 2 illustrates the transformation tv 210 that is needed to achieve the 

objective. The thick lines 212, 214, and 216 representing transformations 7r, and 
respectively, form a sequence of steps that encodes a message x with one key k, converts 
the encoded message into the other one encoded with another key k\ and decodes the 
message using the key k'. The thin lines 218 and 220, representing the transformations 

10 Ex and D k , respectively, show other possible encoding and decoding operations that may 
be performed. 

In many cases, the key space K of an encoding scheme is not merely a set. 
Equipped with some operation K may possess some mathematical structure. For 
instance, the key spaces of all the example schemes given in the previous section can be 
15 equipped with some operations to become mathematical groups. Table 1, below, shows 
some of these operations, where ° stands for the composition operator of permutations 
and 

*:(Z;xZ„)x(Z;xZJ^Z>Z n 

is defined as 

20 (a, b) * (a\ b') = (a a (mod n), ab + fc'(mod «)) . 

Table 1 



Scheme 


Key Space **JP' 


Operation 


X 




© (XOR) 


M 


z; 


x (mod ri) 


S 


z„ 


+ (mod n) 


P 


n„ 


° (composition) 


A 


z*„xz n 


* (defined above) 



When the key space K of an encoding scheme (X, K, £, D) is a group with some 
operation " the encoding and decoding transformations may be uniquely determined by 
25 the keys. This happens when the key space K is isomorphic, as a group, to the 
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transformation groups E = {E k \ke K} and D = {D k I ke K) formed by the encoding 
and decoding transformations on the message space X; that is, for any k, k'e K , 

D t and E k <>E k .=E kr 

and 

5 E k = (D k r 1 = D k _ t and D k o D k . = D kk . , 

where ° is the composition operator of the transformations, which is defined as, for 
example, 

E k oE k ,(x) = E k ,(E k (x)) 

for all jte X. 

10 It can be easily checked that all the schemes given in Table 1 above are key- 

determined. Key-determined encoding schemes permit a systematic way to transfer the 
right to decode messages from one key holder to another. With the isomorphism between 
the key space and the transformation groups, the composition of the decoding 
transformation with one key k and the encoding transformation with another key Id can 

15 then be viewed as the encoding transformation determined by the composed key k~ l * k. 
Let (X, K, £, D) be a key-determined encoding scheme. Suppose y = £*(x) is the encoded 
version of the message xe X with the key ifce K . The right to decode the encoded 
message of x can be transferred from the key holder of k to the key holder of k' in the 
two-step algorithm shown in Figure 3. 

20 First, generate a transfer key t = k' x - k (step 310). Then encode the message with 

the transfer key t according to y' = E t (y) (step 312). 

The algorithm is correct thanks to the property of the key space being isomorphic 
to the encoding and decoding transformation groups. The correctness can be verified as 
follows: 

0 t <(/) = A<(£,(>O) 

= D k .(E k . lr (y)) 
= D k .(E k .(E k Ay))) 
25 =E k Ay) 

= D k (y) 
= D k (E k (x)) 
= x 



15 



The generality of the algorithm makes it immediate to derive the transference 
steps for the example schemes set forth above. Referring again to Figure 3, for the XOR 
Scheme X over B n , to convert y = E k (x) to / = £*<*), first generate a transfer key 

t = k © k' (step 310). Then encode the message with the transfer key t according to 
5 y-y® /(step 312). 

For the Multiplicative Scheme M over Z* , to convert y = E a (x) to y' = E a {x), first 

generate a transfer key t = a'a { (mod n) (step 310). Then encode the message with the 
transfer key t according to / = ty (mod n) (step 312). 

For the Shift Scheme 5 over Z n , to convert y = Eb{x) to y' = Eb{x)> first generate a 

10 transfer key t = b r -b (mod n) (step 3 10). Then encode the message with the transfer key 
t according to / = y + / (mod n) (step 312). 

For the Substitution Scheme P over II n , to convert y = E p (x) to / = E p (x), first 

generate a transfer key t=p l ° p r (step 310). Then encode the message with the transfer 
key t according to / = t(y) (step 312). 

15 As will be described below, it is also possible to transfer the right to decode in 

product schemes of not only key-determined encoding but also commuting schemes. In 
order to define commuting schemes, it is necessary to characterize encoding schemes that 
are essentially equivalent. Suppose that S - (X, K, E, D) and 5' = (X, fC 9 E\ D*) are two 
encoding schemes with the same message space X. S is said to be equivalent to S\ 

20 denoted by S = 5', if there is a bijective (one-to-one and onto) mapping h :K -> K' such 
that for each message xgX and for each key ke K , 

and 

D k (x) = D' h(k) (x). 

25 Clearly, the scheme equivalence relation = is an equivalence relation; that is, it satisfies 
that, for any encoding schemes 5, S\ 5", the following hold: (i) 5 = 5; (ii) 5 = 5' implies 
5' = 5; and (Hi) 5 = 5' and 5 f = 5" imply 5 - 5". Thus, equivalent encoding schemes form 
an equivalence class in that each scheme in the class provides no more and no less 
functionality than any others in the class. 
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The scheme equivalence relation allows one to characterize encoding schemes in 
several ways. An encoding scheme 5 is said to be idempotent if S 2 = S. Many of the 
encoding schemes are idempotent, including the XOR, multiplicative, shift, substitution, 
and affine schemes. If a scheme S is idempotent, then there is no point in using the 
5 product scheme S 2 , as it requires an extra key but provides no more functionality. 

Another characterization on encoding schemes using the scheme equivalence 
relation = is that of commuting schemes. Two encoding schemes S and S' are said to 
commute if S x S' = S'x S . Trivially, any scheme commutes with itself. A not-so-trivial 
example is that of the multiplicative scheme M and the shift scheme 5. To see that they 
10 commute, i.e., MxS = SxM , one can compare the equations 

Eb{E a {x)) = ax + b (mod n) 

and 

E a (Eb(x)) = ax + ab (mod n); 

and find out that the mapping 
15 h:K s xK M ->K M xK s 

defined by 

h(b, a) = (a, a x b (mod ri)) 
makes the product SxM isomorphic to the product MxS . 

Product schemes of key-determined and commuting encoding schemes enjoy a 
20 systematic way of transferring the right to decode messages. Let S x xS 2 be the product 
scheme of two key-determined and commuting encoding schemes. Suppose that 
h = (h { ,h 2 ): K 2 xK x — > K x xK 2 is the mapping that makes S 2 x S x isomorphic to 
S x x S 2 , where h x :K 2 xK x ^> K x and h 2 :K 2 xK x —> K 2 . First, observe that the product 
scheme is also key-determined; the product key space K x xK 2 is a group with respect to 
25 the operation * defined by 

This is because 
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£(M 2 > ° E iKA) = E k x ° E kl o E k[ o E ki 

~ E k x ° Efh(k 2t k{) ° E h 2 {k 2 xo ° 

-E 

Now, the right to decode the encoded message of x can be transferred from the 
key holder of k to the key holder of another key k' in the two-step algorithm shown in 
Figure 3. First, generate a transfer key t = (fy (k 2 1 , k~ x k[),h 2 {k 2 ,k~ { •/;')• k' 2 ) (step 
5 310). Then encode the message with the transfer key t according to y' = E t (y) (step 312). 

The correctness of the transference algorithm is verified by the following 
equality: 

= E k? oE ^ k{ oE *'S y) 

= D k2 oD ki oE k[ o Ek ,(y) 
= E k[ oE k ,(x) 

where the last entity can be readily decoded using the key k' - (k' x ,k' 2 ) . 
10 The method is best illustrated with the following example, applying the affine 

cipher A over Z n . Since A = M x S , and M and S are key-determined, commuting 
schemes, the method described above applies to the affine scheme. As seen before, it is 
the mapping h(b, a) = (a, ab) that makes SxM isomorphic to M x 5 . Thus, h x (b, a) = a 
and h2(a y b) = ab (mod n). The transfer key t from (a, b) to (a', can be derived as 

t^ih.ib- 1 ^' 1 a\h 2 {b~\a' x a') b') 
15 ={a-a\h 2 {b-\a x .a) + b') 

= (a'a-\(a'a- l )b~ l +b') 
= {aa\-a'a x b + b') 

Then, to decode y using a second key (a\ b r ), first generate a transfer key 

A 

f = (a'a~\modn)-a'a~ l b + bXmodri))=(t l ,t 2 )(step 310 )- Th en encode the message 
using the transfer key / according to y' = t\y + 1% (mod n) (step 3 12). 
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The methods presented herein for transferring the right to decode messages are 
transitive. This means that two sequential transfers from Alice to Bob and then from Bob 
to Carol are equivalent to a direct transfer from Alice to Carol. It is important to note 
that, in each of the example schemes, a transfer key is also a key of the scheme. 
5 Accordingly, two transfer keys used in the two sequential transfers can be 

combined to form a transfer key for the direct transfer. Take the affine scheme as an 
example. Let k = (a, b), k* = (a\ b'), and k" = (a", b") be the keys for Alice, Bob, and 
Carol, respectively. Then the transfer keys are t = (a'a~ x -a'a~ x b + b') from Alice to 
Bob, f' = (a*d~ x -a"d~ x b' + b") from Bob to Carol, and t* = {a"a~ x -a"a~ x b + b") from 

10 Alice to Carol. It is straightforward to verify that the composition of t and t' as 

keys in the affine scheme yields t": 

t-t 0 = (t[t l9 t[t 2 +t' 2 ) 

= ((a V" 1 )(da~ l ), (a V' 1 ){-da' x b + b') + (-a V"V + b")) 
= (da-\-da x b + b") 
= t" 

In other words, the composition of sequential transfers of the right to decode messages is 
memory-less; all the intermediate transfers will not be reflected in the overall transfer. 

15 It should be noted also that, for the schemes X, Af, and 5, the transfer key 

generation step is equivalent to "decoding" Id with k. Thus, the computation needed in 
the transfer is the same as the one used in the decoding-and-re-encoding method for these 
schemes. One may think that the new method shows no improvement in this efficiency 
regard, but it has been found that the transfer key is message-independent and hence 

20 needs to be computed only once. When the number of messages m involved in the 
transfer increases, this feature will cut the computation required by the re-encoding 
method by half. Moreover, the transfer key t does not leak any useful information on the 
keys k and k\ and a transfer performed according to the methods set forth herein will not 
reveal the message x. These properties make the proposed method appealing when the 

25 security of the message x and the decoding keys k and k! is an issue during a transfer. 

A typical system configuration capable of carrying out the methods described 
with reference to Figure 3 (and described in further detail below) is shown in Figure 4. 
There are three relevant parties in most proxy encryption applications. An Encryptor 
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410, a Grantor A 412, and a Grantee B 414. As will be recognized, the encryption, 
decryption, and other processing operations performed in the invention are facilitated by 
a processor (416, 418, 420) under each party's control. Each processor is equipped with 
memory (422, 424, 426) for data storage and a communication interface (428, 430, 432), 
5 capable of sending and receiving messages. 

Proxy Encryption Schemes 

The rest of the disclosure, directed to more formal proxy encryption schemes, 
10 rather than encoding schemes, is organized as follows. First, a generic proxy encryption 
scheme is described and characterized according to several criteria. The several 
following paragraphs fix set forth notation that will be used throughout the disclosure and 
recall the ElGamal public-key encryption scheme. For the purpose of comparison, this 
disclosure then lists two existing proxy encryption schemes and examines their properties 
15 in comparison to the present invention. Details on the two new proxy encryption 
schemes are then introduced, together with their security and performance analysis. 
Applications of these new schemes to massive document distribution and file protection 
are given thereafter. 

As indicated in the introduction, the goal of proxy encryption is to delegate the 
20 decryption right from one to another in secure and efficient ways. For the discussion that 
follows, it is convenient to define the roles of parties that may be involved in proxy 
encryption. Two most important roles are those of grantor and grantee. A grantor is an 
original key holder of encrypted messages who wants to delegate the decryption right to 
someone else. A grantee is a key holder designated to perform decryption on behalf of a 
25 grantor and thus act as grantor's decryption proxy. In the motivating example in the 
introduction, Alice is the grantor while Bob is the grantee. Other roles may include an 
encryptor who is an one that originally encrypts messages for the grantor, and a 
facilitator who may help to perform some message processing tasks, such as 
transforming messages encrypted for the grantor into messages encrypted for the grantee. 
30 Certainly, it is not necessary that all these roles are played by different parties. For 
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example, a party may play roles of the grantor and facilitator, as in the Mambo and 
Okamoto schemes discussed below. 

With these roles in place, a proxy encryption scheme is just a description of how a 
grantee, possibly with some aid from a facilitator, delegates a grantee the right to decrypt 
5 messages originally generated by an encryptor for the grantee. A proxy encryption 
scheme may consist of four generic steps: message encryption, proxy key generation, 
proxy transformation and message decryption. These steps will be described in further 
detail below, with reference to Figure 5. 

1. Message encryption E: The encryptor generates an encrypted message using 
10 grantor's encryption key and delivers it to the grantor (step 510). 

2. Proxy generation th To delegate the decryption right to the grantee, the grantor 
generates a proxy key it as a commitment token that allows the grantee to decrypt the 
message encrypted for the grantor (step 512). 

3. Proxy transformation II: When necessary, the facilitator performs a proxy 
15 transformation II, possibly using the proxy key 7r, to convert the message encrypted for 

the grantor to a message encrypted for the grantee (step 514). 

4. Message decryption D: Upon receiving the transformed message and possibly 
the proxy key n;, the grantee decrypts the message (step 516). 

Accordingly, it should be observed that the generic scheme above covers the two 
20 straightforward solutions to proxy encryption mentioned in the introduction. The re- 
encryption scheme is a special case where the grantor (Alice) is also the facilitator who 
actually decrypts the message and then encrypts for the grantee (Bob), and the proxy n 
can be considered as a collection of grantor's decryption key and grantee's encryption 
key, which is used only by the grantor and not by the grantee. The scheme of passing 
25 grantor's decryption key to the grantee is another special case of the generic scheme, 
where the proxy key is the decryption key and the proxy transformation is the identity 
transformation. 

However, not all schemes that can be derived from the generic one above are 
qualified as proxy encryption schemes. Intuitively, a proxy encryption scheme has to 
30 satisfy some basic requirements, namely delegation, security, transitivity and 
performance, as described below. 
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Delegation. To ensure that, at the end of the message decryption step, the grantee 
is able to recover the original message correctly, the following equation must hold for 
any message m: 

D(Tl{E{m,e A ),K),d B ,n) = m , 

5 where E(m,e) is an encryption function of message m under encryption key e, 
D{c,d,n) is a corresponding decryption function of encrypted message c under 
decryption key d and possibly proxy key tt, YI(c,tt) is the proxy function that converts 
encrypted message c according to proxy key and e A , e B , d A , and d B are the encryption 
and decryption keys of the grantor A and grantee B, respectively. 

10 In addition to the correctness above, the functionality of delegation should be 

guaranteed. In one form, this means that, after the proxy key is issued and the proxy 
transformation is completed, the message decryption step should require no private 
information from the grantor, and it should be carried out solely by the grantee. In 
another form, this is equivalent to undeniability of the delegation from the grantor; that is, 

15 once the proxy key is created and proxy transformation is performed, the grantor should 
not be able to deny the delegation, without seeking other means such as preventing the 
grantee from obtaining the proxy key and receiving the transformed message. As a 
consequence of this functionality, the grantor's decryption key can be destroyed with 
grantee's decryption key and possibly the proxy key maintaining the ability to decrypt the 

20 message. (This is useful in the file protection application later in Section 6.) 

Security. In essence, a proxy encryption scheme is also an encryption scheme at 
least from the grantee's point of view. The introduction of proxy keys and 
transformations must in no way corn-promise security and privacy of the encryption. 
Thus, it should be at least computationally hard for any unauthorized third party to 

25 recover the original message and decryption keys of the grantor and grantee from 
publicly available information. 

Moreover, forging valid proxy keys by any untrusted party should be very hard. 
It must be clear, though, that generating the proxy key k requires knowledge of at least 
the decryption key of the grantor; otherwise the underlying encryption system is not 

30 secure. 
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Transitivity. Naturally, the proxy relationship should be transitive. After the 
grantor delegates the decryption right, the grantee should be able to act as a new grantor 
to delegate the right further to another grantee, by just following the same scheme. 
Moreover, it should be possible for someone, say the first grantor, to delegate the right 

5 directly to a new grantee by combining all intermediate proxy keys into one proxy key 
and composing all consecutive proxy transformations into one transformation. 

Performance. As the re-encryption scheme is an intuitive, straightforward 
solution to proxy encryption and it satisfies the above delegation, security and transitivity 
requirements, any practically useful proxy encryption scheme should have no degradation 

10 in computational performance when compared with the re-encryption scheme. 

Proxy encryption schemes may vary according to their application requirements. 
They can be categorized according to many aspects. Obvious ones include whether they 
are public-key or private-key based, and whether their security measures are perfect in 
the information theoretical sense or rely on intractability of some computational 

15 problems. The following aspects ones are related to the proxy key and transformation. 

Confidentiality. While secrecy of messages and decryption keys has to be 
enforced, secrecy of proxy keys and proxy transformations may not be a mandatory 
requirement. A scheme is called public if proxy keys it generates may be published 
without compromising its security and proxy transformations applied in untrusted 

20 environments; otherwise, the scheme is private. In a private scheme, when a proxy key is 
transferred from the grantor to the facilitator and grantee, care must be taken to protect 
the proxy key from disclosure. As a result, the proxy transformation which uses the 
proxy key must be performed in private as well. 

Commutativity. In terms of messages, the grantee must be unconditionally trusted 

25 by the grantor, since proxy encryption by definition allows the former to decrypt on 
behalf of the latter. However, the trust model may be different for their private 
information. A proxy encryption scheme is commutative if the grantor and grantee have 
to trust each other with regard to their private keys; otherwise, it is non-commutative. A 
commutative example is that the proxy key is such created that either one of the grantor 

30 and grantee can obtain other's decryption key from it. Whenever this is the case, the 
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proxy encryption mechanism may be simplified to a key exchange protocol that allows 
the grantee to use grantor's decryption key to decrypt the encrypted messages directly. 

Generality. In many cases, the grantor wants to restrict the scope of the delegated 
decryption right. Often intended restrictions include that the proxy key may only be used 

5 by a designated grantee, that the proxy key may only be applicable to a specific message, 
or that the proxy transformation may only be applied by a specific facilitator. For 
example, when a proxy encryption scheme is used in some applications like key escrow, 
it would be ideal that proxy keys are independent of messages they will apply to. But for 
occasional delegation such as securely specifying inheritance in someone's will, it may 

10 be highly desirable that a proxy key can only be restricted to a designated party (e.g., a 
grandchild), applicable to a specific message (e.g., some portion of the will) and possibly 
used in the proxy transformation by a particular party (an attorney). 

Degenerateness. When used in the extreme situation where the grantor and 
grantee are a same person with a same decryption key, a proxy encryption scheme should 

15 reduce to a regular encryption scheme, without introducing any complications (such as 
non-trivial proxy keys and transformations, and the requirement of an extra facilitator). 

As will be shown below, the Mambo and Okamoto schemes are private and non- 
commutative. Proxy keys in their schemes can be either message-independent or 
dependent but are not restricted to designated grantees. The Blaze and Strauss scheme is 

20 just opposite: it is public but commutative, and its proxy keys are message-independent 
but uniquely associated with designated grantees. In comparison, the schemes according 
to the invention set forth herein are public and non-commutative, and their proxy keys are 
message-dependent and restricted to designated grantees. 

25 Proxy Encryption Using the ElGamal Cryptosystem 

As the proxy encryption schemes discussed below in this disclosure will all be 
based on discrete logarithms in multiplicative groups, a formal setting which is common 
to all these encryption schemes is hereby adopted. The notation used herein recalls the 
30 ElGamal encryption scheme. Encryption schemes based on discrete logarithms are 
particularly advantageous because of their technical advantages over RSA-type schemes 
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and their natural generalizations to many finite groups such as elliptic curve groups over 
finite fields. 

As set forth above, for any natural number n, let Z n = {0,l,...,n-l} denote the 
ring of integers modulo n, and let Z* = {me Z n I gcd(m,n) = 1} denote the multiplicative 
5 group of Z n . Note that, when n is a prime, Z* = {l,...,n-l} . For a modulo n and a 
number a that is relatively prime to /z, let a A denote the multiplicative inverse of a 
modulo n; that is, a 1 is the element that satisfies aa~ x = l(modn) . 

An element a of Z* is said to be of order m if the number of its powers modulo n 
is m. A generator g of Z* , if it exists, is an element of order I Z* I (the size of Z* ); in 
10 this case, Z* is a cyclic group. When n is a prime, every element of Z* except 1 is a 
generator of Z* . 

Let Z* be a cyclic group with a generator g. The discrete logarithm of an 

element x to the base g, denoted as log^ jc, is the unique integer a, 0 < a < n - 1 , such that 
x = g a (mod n). The discrete logarithm problem is that, given a prime p, a generator g of 
15 Z* , and an element x e Z* , find the integer a, 0<a</?-2, such that g a s jc(mod p) . 

A very closely related problem is the Diffie-Hellman problem: given a prime /?, a 
generator g of Z* , and elements g fl (modp) and g^(modp), find g^modp). The 

discrete-logarithm problem is at least as hard as the Diffie-Hellman problem, because any 
solution to the former problem can be used to solve the latter problem. 
20 The ElGamal encryption scheme shown in Figure 6 is a part of a discrete- 

logarithm based, public-key cryptosystem proposed by ElGamal for both encryption and 
digital signature. See T. ElGamal, "A public key cryptosystem and a signature scheme 
based on discrete logarithm," IEEE Trans, on Information Theory, Vol. 31, pp. 465-472 
(1985). 

25 Referring now to Figure 6 in detail, the ElGamal scheme is set up (step 610) by 

establishing two public parameters p and g, where p is a prime (typically 512 bits in 
length), such that p-l has a large (typically 160 bit) prime factor q (e.g., /?=2#+l) and g is 
a generator in Z* . A private key for a user is set (step 612) by uniformly choosing a 



25 



random number aeZ* p _ x . Its related public key is calculated (step 614) as 

a = g a (mod p) . The user publishes a and keeps a secret. 

To encrypt a message m to be sent to user A with public key a, a random number 

hZ*_, is uniformly chosen (step 616), and a pair of numbers (r,s), together 

5 representing the encrypted message to be sent to A, is calculated (step 618) as follows: 

r = g k (mod p) and s - ma k (mod p) . 

To decrypt the message (r,s), the recipient A recovers the message m (step 620) 
by calculating 

m = s(r a )~ l (mod p) . 

10 Note that the selection of the public parameters is intended to establish equation 

g p ~ l (mod p) = 1 (Fermat's little theorem). These parameters should be authentically 
known to all users. They can be chosen, say, by some trusted authority. Also, the way 
that private key a is chosen ensures that the inverse a' 1 of a modulo p-l exists and is 
unique. 

15 Unlike the RSA public-key encryption scheme, the ElGamal scheme is non- 

deterministic, since the encrypted message also depends on the random number L 
Indeed, it is similar in nature to the Diffie-Hellman key exchange protocol; the key 
established between the sender and receiver for encrypting and decrypting the message m 
is g** (mod p) from r = g k (mod p) (part of the encrypted message) and a = g a (mod p) 

20 (the public key of A). Nevertheless, the security of the ElGamal encryption scheme relies 
on the intractability of the discrete logarithm problem and the Diffie-Hellman problem. 
To date, practice in seeking optimal algorithms for the discrete logarithm problem has not 
found any efficient (polynomial-time) solution. It is similar to the situation for the 
integer factorization problem upon which security of the RSA scheme is based. 

25 Moreover, it has also been shown that, for some primes p, solving the discrete logarithm 
problem is at least as hard as solving the factorization problem of a same size. This 
implies that for those /?s, the ElGamal scheme is at least as secure as the RSA scheme. 

Very recently, several proxy encryption schemes have been proposed. All these 
schemes follow the generic proxy encryption scheme in delegating the decryption right: 

30 the encryptor sends an encrypted message to the grantor A, who then delegates the 
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decryption right to grantee B by creating the proxy key, and after the proxy 
transformation is completed the grantee B finally decrypts the message. Two 
representative and known proxy encryption schemes are presented below: one from 
Mambo and Okamoto and the other from Blaze and Strauss, both of which are variations 

5 on the ElGamal scheme. Since they have the same scheme setup as the ElGamal scheme, 
the setup (see steps 610-614 of Figure 6 above) is omitted from the presentation. 

Mambo and Okamoto have proposed three proxy encryption schemes: two are 
based on the ElGamal scheme and the other is based on the RSA scheme. The one shown 
in Figure 6 and described below is ElGamal-based and shares its basic features with the 

10 other two schemes. 

Referring now to Figure 7, given a message m that needs to be sent to a grantor A 
with public key a, the message m is encrypted by uniformly choosing a random number 
hZ* H (step 710) and calculating a pair of numbers (r 9 s) representing the encrypted 
message (step 712) as follows: 

15 r = g k (mod p) and s = ma k (mod p) . 

To delegate the decryption right to a grantee B, the grantor A creates a proxy key 
7r by uniformly choosing a random number ae Z*_j (step 714) and calculating 
K = aa\mod(p-l)) (step 716). Then, A delivers the proxy key it to B (step 718) in a 
secure manner (e.g., by encrypting it with B's public key) and keeps the value of a' 

20 private. 

To allow B to decrypt the message, A calculates r -r a 1 (mod p) , where a~ x is 
the multiplicative inverse of a! modulo p-\ (step 720). The pair {r\ s) is the transformed, 
encrypted message to be sent to B. 

Upon receiving the transformed message (r', s) and the proxy key 7r, B decrypts 
25 the message m (step 722) by calculating m = s(r'* )" 1 (mod p) . 

This proxy encryption scheme uses the encryption and decryption components of 
the ElGamal scheme, except ZTs private key is replaced by the proxy key n. It is correct 
because, when using n to decrypt the transformed message (r', s), the following holds: 

s((rTy l (mod p) = sir™'*" )" 1 (mod p) = mg* a (g*T 1 (mod p) = m. 
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The security of this scheme is evaluated in two aspects. The complexity for 
anyone, including the grantee B, to discover grantor A's private key a based on all the 
available information is as same as the one for solving the discrete logarithm problem. 
The difficulty for anyone, even with the proxy key, to impersonate A to transform the 
5 encrypted message (i.e., to generate (r' 5 s)) is the same as the one for solving the Diffie- 
Hellman problem. 

This scheme has several very appealing features. First, its security implies that it 
is hard for B to recover A's private key. In this sense, there is no need for A to trust 
and hence the scheme is non-commutative. Second, the proxy key n generated is 

10 message-independent. B can use it to decrypt all the messages transformed by A. Third, 
this scheme satisfies the transitivity requirement. Upon receiving both the proxy key it 
and the transformed message (r' ? s), the delegated user B can further delegate the proxy to 
another user C, by treating k as the private key a and (r^ s) as (r, s) and repeating the 
proxy generation and transformation. Fourth, the scheme requires less computational 

15 efforts than the re-encryption scheme. 

However, implementing proxy encryption in the manner of this scheme has 
several shortcomings. First, the proxy key contains no information about the delegated 
grantee B\ it is solely derived from grantor A's private key. Moreover, the message 
decryption performed by B does not need B's private decryption key either. 

20 Consequently, the message can be recovered by anyone that gets hold of the proxy key 
and encrypted message, not necessarily B. Thus, B can ask anyone to decrypt the 
message by directly passing the proxy information. In many cases, this is not desirable; 
A should be able to specify the key holder who is to act on A's behalf. 

Second, the proxy key it has to be a secret between A and B and needs to be 

25 transmitted from A to B in a secure manner. As a result of n containing no information of 
B and (r' 5 s) being possibly communicated in public, revealing tz is essentially equal to 
disclosing the message. 

Third, the proxy transformation has to be conducted by A. The value a! used in 
the transformation is a secret to A and it is vital to preventing B from knowing A's 

30 decryption key a. 
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In short, the scheme is non-commutative and message-independent, but private 
and unable to specify the designated grantee. 

Blaze and Strauss have described another public-key proxy encryption scheme. 
As can be seen in Figure 8, the scheme is similar in structure to ElGamal encryption, but 
5 with the parameters used differently and the inverse of the secret used to recover the 
message. 

Turning now to Figure 8 in more detail, given a message m that needs to be sent 
to a grantor A with public key a, the message m is encrypted by uniformly choosing a 
random number k e Z* p _ { (step 810) and calculating a pair of numbers (r, s) representing 
10 the encrypted message (step 8 12) as follows: 

r = rag* (mod p) and s = a k (mod p) . 
To delegate the decryption right to a grantee B, the grantor A creates a proxy key 
7r by obtaining B 9 s private decryption key b (step 814) and computing 
K = a -1 fc(mod(p-l)) (step 816), where a 1 is the inverse of the private key a of A 
15 modulo p-l. The proxy key n can be made public. 

To use the proxy key n to convert a message (r, s) encrypted for A to a message 
encrypted for B 7 the facilitator (not necessarily A, since the proxy key k is public) 
computes s - s n (mod p) (step 818). The pair (r, s') represents the transformed 
encrypted message, which can then be transmitted to B. 
20 To decrypt the transformed message, B computes m = r(s' b V* (mod/?) (step 

820), where b is 2Ts private key and b A is the inverse of b modulo p-l . 
The scheme is correct, since in the message decryption 

s' b * = g* (mod p) and m = r(g k ) _1 (mod p) . 
The scheme is secure in that the message m and secret keys a and b cannot be recovered 
25 from the encrypted messages and public keys. Moreover, publishing the proxy key 
compromises neither the message m nor the secret keys a and b. More precisely, the 
problem of recovering m from the public information (a, /?, r, s, it, S*) is as hard as the 
Diffie-Hellman problem. 

In contrast to the previous scheme, the last security feature makes it unnecessary 
30 to keep the proxy key k private. Thus, the grantor A can publicly send n to whoever 
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(facilitator) is to perform the proxy transformation, or can simply publish it. Moreover, 
the scheme does not require any secret from A in order to carry out the proxy 
transformation, and consequently it allows anyone, trusted or not, to perform the 
transformation and hence eliminates the necessity of A' s, as well as ZTs, presence in the 
5 transformation. 

Also unlike the previous scheme, there is no difference to the user B between 
decrypting a regular encrypted message and decrypting a proxy transformed message. 
This elegant feature allows the user B to treat all incoming encrypted messages 
uniformly. In fact, it is possible for an untrusted facilitator or server to perform the proxy 

10 transformation and then forward the message to the user B. 

In spite of these desirable features, this scheme is commutative; the involved key 
holders A and B must trust one another bilaterally. B can learn A 9 s secret key a (by 
multiplying the proxy key by b~ x ). In addition, the proxy key is also message- 
independent, as it is in the previous scheme, which delegates B the right to decrypt all 

15 messages encrypted for A's private key a. Accordingly, this scheme is public and 
message-independent but commutative. 

Two proxy encryption schemes according to the invention are presented herein, 
and then analyzed in regard to their security, commutativity and performance. Like the 
private proxy scheme, they are non-commutative, and at the same time, they support 

20 public proxy keys and transformations in the fashion the commutative proxy scheme 
does. However, they differ from the private and commutative schemes in that they are 
message dependent. Moreover, their overall performance is better than the ElGamal- 
based re-encryption scheme. 

Again, these schemes share the same scheme setup of the ElGamal scheme, and 

25 they assume that a grantor A delegates the decryption right to a grantee B. 

To understand how to adapt the ElGamal scheme into a proxy encryption scheme, 
it is helpful to examine some details of the ElGamal scheme. It should be noted that the r 
component of the encrypted message m is independent of the recipient A's private key a 
and public key a. As s = ma k (mod p) = mg ka (mod p), a is only used in the s 

30 component, and a is implicitly embedded in s's exponent. Thus, it is sufficient for the 
proxy transformation to convert the message encrypted for A into the message encrypted 
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for B by removing A's private key a from s and replacing it with B's private key b. In 
order to prevent B from obtaining A's private key a, the function to generate the proxy 
key must be somehow "one-way." Indeed, this can be achieved with aid of the random 
number k as follows: 
5 7t = g k(b - a) (mod p); 

Consequently, the proxy transformation that completes the message conversion should 
look like the following: 

s' = s7T(mod p) = mg ka g Hb ~ a) (mod p) = mg kb (mod p) . 
The above discussion leads to the scheme in Figure 9. It turns out that the proxy 
10 key and transformation satisfy the security requirement and provide desired being-public 
and non-commutativity features. 

Referring now to Figure 9, given a message m that needs to be sent to a grantor A 
with public key a, the message m is encrypted by uniformly choosing a random number 
ke Z* p _ x (step 910) and calculating a pair of numbers (r, s) representing the encrypted 
15 message (step 912) as follows: 

r = g * (mod p) and s = ma k (mod p) . 
To delegate the decryption right to a grantee B, grantor A creates a proxy key tz by 
obtaining B's authentic decryption key b (step 914) and calculating it = r h ~ Q (mod p) 
(step 916). 

20 The message is transformed from (r, s) to (r, s r ) by calculating s' = s7t(mod p) 

(step 918). The message m is then decrypted by B from (r, s 1 ) by computing 
m = s\r b y x (mod p) (step 920). 

Clearly, this scheme uses the message encryption and decryption steps of the 
ElGamal scheme. It is correct as the message m can be recovered from 

25 s\r b ) _1 (mod p) = sx(r b )~ x (mod p) = mg ak g * ( *" a) (g® )" 1 (mod p) = m. 

A nice feature of this scheme is that, not only do regular and proxy encrypted 
messages appear no different to the grantee 5, but also the scheme coincides with the 
ElGamal scheme when A and B are the same user with the same key; in this case, the 
proxy value k is equal to 1 and the proxy transformation is the identity transformation. 
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It is easy to see that the scheme is transitive. Upon receiving the proxy 
transformed message, the grantee B can act like the grantor A to further delegate the 
decryption right to, say, another grantee C by repeating the proxy generation step with the 
keys b and c in place of a and b, 

5 Also like the commutative scheme, the proxy generation step requires both A's 

and Z?'s private keys in order to generate the proxy key tt. As an alternative, this step can 
be carried out by anyone that is trusted by both A and B. As noted above, A's private key 
is definitely needed, as otherwise anyone can issue a proxy key to recover the message 
and the underlying encryption scheme is not secure. To establish and communicate B's 

10 private key b, many key-exchange protocols such as the Diffie-Hellman key exchange 
may be used. As shown in further detail below, in some practical applications the 
requirement of the key b either is not a problem or can be relaxed. 

But unlike the private and commutative schemes, this scheme does not make it 
easy for the grantee B to decrypt messages encrypted for A other than the intended one. 

15 Clearly, the proxy key k contains a piece of information that is specific to the encrypted 
message m, namely, the random number k. In this sense, the proxy scheme is message- 
dependent. Moreover, the scheme is non-commutative in the sense that it is hard for B to 
discover A's private key a. This fact, together with the performance of the scheme will 
be established after presenting the next scheme. 

20 Note that, in the previous scheme, the proxy transformation only changes the s 

component of the encrypted message. Since s is the part that actually carries the 
information about the message m, the scheme may not be efficient when m is a very long 
message. For example, the proxy key generated would be as long as the message and the 
effort spent in the proxy transformation would be linear with regard to the length of the 

25 entire message. 

The scheme presented in Figure 10 tends to improve this situation. It uses the 
message encryption step of the commutative scheme in which the message m is shifted 
from s to r. Its proxy key and transformation now have no direct dependence on the 
message m. 

30 As shown in Figure 10, given a message m that needs to be sent to a grantor A 

with public key a, the message m is encrypted by uniformly choosing a random number 
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ke Z*_, (step 1010) and calculating a pair of numbers (r, s) representing the encrypted 
message (step 1012) as follows: 

r - mg k (mod p) and s = a k (mod p) . 
To delegate the decryption right to a grantee B, grantor A creates a proxy key 7t by 
5 obtaining B's authentic decryption key b (step 1014) and calculating 

71 = (s a 1 ) b ~ a (mod p) (step 1016), where a" 1 is the inverse of a modulo p-\. 

The message is transformed from (r, s) to (r, 5') by calculating s' = s/r(mod p) 

(step 1018). The message m is then decrypted by B from (r, s') by computing 

m = r(s /6 1 ) _1 (mod p) (step 1020), where b' x is the inverse of b modulo p-\. 

10 This scheme is correct since 

r{s b ' X ) _l (mod p) = r{{s7t) b ~ { y x (mod p) 

= r((s(s a ' l ) h - a f i y l (modp) 

= r((g ka g kib - a) ) b ~ l r l (mod p) 
= r((g kh f l y\modp) 
= mg k (g k )~ l (mod p) 
— m 

Other properties of this scheme can be verified in the same way as the previous scheme. 
Due to their similarity in nature, only the first of the two new schemes is analyzed 

in this section in regard to its security and non-commutativity. An almost same 
15 discussion can be carried out for the second scheme. In addition, though the first scheme 

(as well as the second scheme) is transitive and its security may involve more than two 

key holders, the analysis to be given only considers the two-key-holder case; the general 

case is also similar. For presentation clarity, the phrase "(mod p)" will be omitted in this 

subsection; its occurrence should be clear from context. 
20 Recall that, other than the scheme parameters (p, g), the public information 

available from the scheme includes 

a = g\ fi = g b , r = g k , s^mg*, n = g k{b - a \ s' = mg bk . 
For the reasons set forth below, the scheme is computationally secure. It is hard 
to recover the message m and secret keys a and b from the public information, provided 
25 that the Diffie-Hellman and discrete-logarithm problems are hard to solve. Since the 
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proxy key is part of the public information, this implies publishing it compromises 
neither the message nor the secret keys. A consequence of this is that it is also hard for 
anyone to forge a valid proxy key in a systematic manner. Beyond that, the scheme is 
shown to be non-commutative in the sense that even with B's private key, it is still hard 

5 to recover A's private key. If the proxy key is indeed generated by a third party trusted 
by both A and B, this fact implies that it is not necessary for B to trust A either. This is a 
significant improvement over the commutative scheme. 

Moreover, as stated above, the proxy encryption schemes of the invention are 
more efficient than re-encrypting a message. Below, in Table 2, is the performance of the 

10 two proxy encryption schemes according to the invention described herein compared 
with the re-encryption scheme using the ElGamal algorithm, in terms of the amount of 
computation they require. In Table 2, the numbers of multiplication operations, 
exponentiation operations, and inversions, all performed modulo /?, are listed for these 
schemes. 

15 Table 2 



Operations 


Re-Encryption 


First Scheme (Fig. 9) 


Second Scheme (Fig. 10) 


mult. 


exp. 


inv. 


mult. 


exp. 


inv. 


mult. 


exp. 


inv. 


Encryption 


I(x2) 


2(x2) 


0(x2) 


1 


2 


0 


1 


2 


0 


Proxy Key Gen. 








0 


1 


0 


0/1 


2/1 


1/0 


Transformation 








1 


0 


0 


1 


0 


0 


Decryption 


l(x2) 


l(x2) 


l(x2) 


1 


1 


1 


1 


1 


2/1 


Total 


4 


6 


2 


3 


4 


1 


3/4 


5/4 


3/1 



Note that the total number of operations for re-encryption using the ElGamal 
scheme is twice the number of operations for a single ElGamal encryption and 
decryption, since the message must first be encrypted, then decrypted, then re-encrypted, 

20 then re-decrypted. Moreover, the computation in the second scheme can be optimized by 
(i) pre-computing the inverses a' 1 and b~ l in the scheme setup step and (ii) multiplying the 
two exponential components (modulo (p-1)) in the proxy generation step instead of using 
two exponentiations. The second set of numbers under the second scheme result from 
this optimization. Overall, the inventive proxy encryption schemes presented herein have 

25 better performance than the simple, ElGamal-based re-encryption scheme. 
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A pplications 

Public and non-commutative proxy encryption schemes provide a key mechanism 
5 for implementing a wide range of applications. Massive document distribution and file 
protection are two key motivations for this disclosure. These applications correspond to 
two typical situations for proxy encryption. The former is related to the case where the 
grantor is the one who encrypts the message at the first place, while the latter is to self- 
delegation in which the grantor and grantee are the same key holder but with different 
10 keys. 

Again, note that a document refers to any digital file whose content could text, 
graphics, audio, video, executable or even multi-media. Usually, a document is large in 
size, even after compression. Because public-key algorithms tend to be very slow when 
compared with conventional private-key algorithms such as DES, IDEA and RC4, and 

15 private-key algorithms require establishing secret keys to begin with, the most practical 
approach to massive and secure distribution of documents over networks is to combine 
the private-key and public-key encryption mechanisms. Typically, an efficient private- 
key algorithm is used to encrypt the document by using a randomly generated key, called 
the session key, and the public key for each document recipient is used to encrypt this 

20 session key. Recipients use their private keys to recover the secret session key and then 
use it to decrypt the document. 

Indeed, the above document distribution approach has the proxy encryption 
flavor; the owner encrypts the document first using a private-key scheme and then grants 
the decryption right, upon request, to its recipients via a public-key scheme. It turns out 

25 that, either one of the two new proxy encryption schemes can be used to combine the best 
features of the approach into a single, normal encryption scheme. 

Take the second scheme set forth above (Figure 10), for example. Two 
observations are in order. First, the component r of the encrypted message can be 
generated using any private-key encryption scheme with K = g*(mod p) as the secret 

30 session key. Accordingly, the message m can be recovered in the message decryption 
step by its corresponding private-key decryption using the secret session key 
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K' = s' b (mod p) = K . In fact, the secret-key encryption scheme used in the scheme is 

r = E K (m) - mK (mod p) for encryption and m - D r (r) = rK'~ { (mod p) for decryption. 

Another simple example is the encryption scheme based on bit-wise XOR ( © ). In this 

case, the computation of r and m can be replaced by 
5 r = E K (m) = m® K and m = D K (r) = r® K . 

Certainly, more sophisticated private-key encryption schemes such as DES and triple- 

DES can be employed if stronger security is needed. 

The second observation is that, if the grantor A is the one who encrypts the 

message m, then A can keep the random number k private and use ZTs public key 
10 P = g*(mod p) , instead of B's private key b, to generate the proxy key: 

7T = (fia- l ) k (modp), 

where a is A's public key. This eliminates the requirement for fi's private key b (or key 
exchange between A and B), and implies that B does not have to trust A, either. 

These two observations lead to the document distribution scheme shown in Figure 

15 11, which is based on the second proxy encryption scheme according to the invention set 
forth above (and in connection with Figure 10). In the scheme, a private-key encryption 
scheme is used to encrypt the message just once for all recipients, while a less expedient 
proxy-key portion is used to encrypt a small amount of information - the session key - 
customized once for each recipient. A beneficial feature of this scheme is that the 

20 encrypted document can be stored in a publicly accessible repository, and the proxy 
transformation can be performed by the document owner A, the recipient B, or the 
repository where the document is physically stored, depending upon the needs of real 
document management and distribution systems. 

Referring now to Figure 11, the scheme is set up the same way as a standard 

25 ElGamal scheme (see Figure 6, described above). In addition, a symmetric, private-key 
encryption scheme is selected (step 1110). Its encryption function is mn E K (m) and 
decryption function is r D K (r) , where K is some private key. 



36 



To encrypt a document m, owner A first chooses a uniformly random number 
keZ* p _ } (step 1112) and calculates a session key K = g k (modp) (step 1114). The 
encrypted document (r, s) is then calculated as follows: 

r = E K (m) and s = A' "(mod p) . 
5 (step 1 1 16), where a is A's private key. A keeps the pair (s, k) private. 

Upon request from a recipient B for the encrypted document (r, s), A first obtains 
B's authentic public key /? (step 1118) and retrieves k from the pair (s, k) (step 1 120). A 
then computes K B - fi k s~ x (mod p) (step 1 122), where s A is the inverse of s modulo /?, as 
the proxy key for B. 

10 The document is then transformed by computing s' = sn B (mod p) (step 1124); 

the pair (r, s') represents the transformed document customized for B. 

To decrypt the customized document (r, s') and retrieve the original document m, 

B first recovers the session key by calculating K = s' b 1 (mod /?) (step 1126), where b~ x is 
the inverse of b modulo Then the document itself is decrypted by calculating 

15 m = D K {r) (step 1128). 

As described above, an adaptation of the present invention is also applicable to a 
file protection application. Usually, file protection in insecure systems such as laptops 
and networked hardware involves long-term encryption of files. Thus, encryption keys 
used for file encryption have much longer lifetimes than their communication 

20 counterparts. While a user's primary, long-term, secret key may be the fundamental 
representation of a network identity of the user, there is a danger that it might get 
compromised if it is used for many files over a long period of time. If the primary key is 
lost or stolen, not only are contents of the files encrypted with it disclosed, but also the 
user loses personal information based on the key such as credit card account, social 

25 security number, and so on. Therefore, it is often preferable to use an on-line method in 
which a new decryption key is derived from the primary key every time a file needs to be 
encrypted and gets updated on a regular basis. 

With the proxy encryption schemes set forth herein, new decryption keys can be 
generated and constantly updated through self-delegation to keep them fresh. Once a 
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new key is created and a corresponding proxy key generated, the old secret key can be 
destroyed, with the new key and proxy key maintaining the ability to decrypt the file. 

Figure 12 shows a file protection scheme that uses a smart card to store and 
update decryption keys. It is again based on the second proxy encryption scheme 
5 presented herein, as illustrated in Figure 10. 

As shown in Figure 12, to encrypt a file m, a processor embedded in a smart card 
chooses a random number k e Z*_, (step 1210) and computes 

r = rag* (mod p) and s - (g*)*(mod/?) 
(step 1212), where a is the smart card's private key. The pair (r, s) represents the file m 
10 in encrypted form. 

Whenever necessary or desired, for example every few weeks or after a 
predetermined number of document accesses, the smart card generates another uniform 

random number a'e Z* p _ Y (step 1214) and computes s' = (s a V (modp) (step 1216), 

where a 1 is the multiplicative inverse of a modulo p-1. The encrypted file (r, s) is then 
15 replaced with (r, s') (step 1218), and the decryption key a is replaced with a new 
decryption key a 1 (step 1220). These steps 1214-1220 can be repeated as many times as 
desired. 

To recover the original file m from its encrypted version (r, s), the processor on 
the smart card uses the latest decryption key a to compute m = rs a ' (mod p) (step 1222). 
20 Note that the file encryption step can start with any secret key it generates, not 

necessarily the smart card's private key. 

To keep encrypted files fresh by updating encryption data with a piece of smart- 
card-generated information helps to maintain single useful copies of protected files. This, 
in some sense, provides copy protection as well. Moreover, the non-commutativity of the 
25 scheme renders previous copies of the files useless, as the corresponding secret 
information stored in the smart card has been changed (and preferably destroyed). 
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Proxy Encryption Using the Cramer-Shoup Cryptosvstem 

Although the foregoing examples and algorithms all employ various adaptations 
of the ElGamal cryptosystem, it should be noted that other cryptosystems can also be 

5 adapted by a scheme according to the invention. 

For example, the Cramer-Shoup public-key cryptosystem is a recently proposed 
cryptosystem that is the first practical public-key system to be provably immune to the 
adaptive chosen ciphertext attack. See R. Cramer and V. Shoup, "A Practical Public Key 
Cryptosystem Provably Secure against Adaptive Chosen Ciphertext Attack," Proceedings 

10 of CRYPTO '98, Springer Verlag LNCS, vol. 1462, pp. 13-25 (1998). The adaptive 
chosen ciphertext attack assumes that the attacker can obtain decryptions of any chosen 
ciphertexts other than the target ciphertext. For example, if the target ciphertext for 
which the plaintext is wanted is c, then the attacker is assumed to have access to a 
"decryption oracle" which will decrypt any ciphertext except c, including for example 

15 c+1, 4c, etc. RSA and ElGamal fall easily to this kind of attack. A different, but 
equivalent, notion of security against active attacks is called non-malleability; however, 
known non-malleable systems are not practical. 

Set forth below in Figure 13 is a description of a hash-free version of the Cramer- 
Shoup cryptosystem, the security of which is based strictly on the Diffie-Hellman 

20 decision problem for an arbitrary group. Thereafter, how to delegate the right to decrypt 
in a Cramer-Shoup scheme will be illustrated in two different situations. 

Referring initially to Figure 13, the system is set up by choosing G as a group of 
prime order where q is large (step 1310). The system assumes that cleartext messages 
are (or can be encoded as) elements of G, and ciphertext messages are elements of 

25 G 4 = GxGxGxG; that is, a ciphertext message is four times as long as its 
corresponding plaintext message. 

A good example of the group G is the subgroup of order q in the multiplicative set 
Z* for some large prime p = 2#+l. In this case, a message m from the set {1,...,^} can 

be "encoded" by squaring it modulo /?, resulting in an element in G, and the message m 
30 can be recovered from its encoding by computing the unique square root of its encoding 
modulo p, in the set {!,...,#} . 
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A key is generated as follows. First, random elements g,,g 2 e G are chosen 
(step 1312), and random elements x {9 x 29 y U9 y {2 , y 2{ , y 22 , y 3I 9 y n9 zeZ q are chosen (step 

1314). Next, the group elements c = g?g? , d x = gpg** , d 2 = g^g y » , d, = gf»g>* , 
and h = g x are computed (step 1316). The public key is then calculated to be 
5 (gpS2' c ^i^2'^3^) ( ste P 1318) and the private key is calculated to be 

(^P^Jll^^JlP^^BP^^) ( ste P 132 °)- 

Given a message me G , the encryption method begins by choosing reZ q at 
random (step 1322). Then the ciphertext (u X9 u 2 ,e 9 v) is calculated as follows (step 1324): 
u x = g[ 9 u 2 =g r 2 ,e = h r m , and v = c f d? T d u *d% . 
10 Given the ciphertext (w 19 ii 2 ,e,v), the corresponding decryption algorithm first 

tests if v = Wl Xl+WlJ ' I!+U2y2!+ ^ I M^ +Uiyi2+U2) ' 22+ ^ 2 (step 1326). If not, the decryption effort is 
rejected (step 1328). Otherwise, the message m is calculated as m = e/uf (step 1330). 

The correctness of a cryptosystem can be verified by checking that the decryption 
of an encryption of a message yields the message. In this case, since w, = g[ and 
15 u 2 = g r 2 , one has u* l u% = g* l g 2 2 = c r . Likewise, 

uwxi+wi^uwxi^y*^ =c r d? r d u 2 ir dl r and u\ =h r . 

Therefore, for the valid ciphertext, the test performed in the decryption algorithm will 
pass. 

The security of this cryptosystem relies upon the difficulty in solving the Diffie- 
20 Hellman decision problem. An algorithm that solves the Diffie-Hellman decision 
problem is a statistical test that can effectively distinguish the following two 
distributions: (a) random quadruples (g l ,g2*u l9 u 2 )e G 4 , and (b) random quadruples 
(Si»£2' m p w 2) g G 4 , where g\ 9 g 2 are random and u x = g[ and u 2 = g 2 for some random 

25 Related to the Diffie-Hellman decision problem are the Diffie-Hellman problem 

(given g, g x , and g^ 9 compute g^), and the discrete logarithm problem (given g and g x 9 
compute x). Within polynomial time, the Diffie-Hellman decision problem can be 
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reduced to the Diffie-Hellman problem which in turn can be reduced to the discrete 
logarithm problem. It is this relationship between the three problems that leads to the 
possibility of delegating the right to decrypt for the Cramer-Shoup system. 

Assume that someone wants to delegate the right to decrypt from a delegator 
5 (Alice, A) to a delegatee (Bob, B). Suppose that Alice has the public key 
(g x ,g 2 ,c,d { ,d 2 ,d 3 ,h) and the private key (x x ,x 29 y u ,y l29 y 2l9 y 22 ,y 31 , y n ,z), and that 
Bob has the public key (g',g' 2 ,c\d x \d' 2 ,d' 3 ,h') and the private key 

✓ ////// / f f \ 

\ X \ ' X 2 ' ^1 1 ' > y 21 ' ^22 '^31' ^32 ' Z ) ' 

Recall, that for a given plaintext message me G , the ciphertext message for 
10 delegator A is M = (M,,M 2 ,e,v), where u x =g x r , u 2 =g 2 , e = h r m, and 
v = c r d^ r d\ r . Similarly, if the message m is directly encrypted for the delegatee B, 
the ciphertext message is M' = (u l9 u 2 ,e\v') 9 where u[ = g[ r , u 2 - g 2 , e =h' r m, and 
v' = c r d[ Uir d 2 lT d'" , where r' is also a random number from Z q . Note further that 

v = (cd?d?d;y and v' = (c'd'*d' 2 *d'/y . 

15 Based on the ideas set forth above, to delegate the right to decrypt from A to B 

involves generating a transfer key it, using that transfer key to transform M into M\ In 
the following, it is assumed that the components g[,g 2 of ZTs public key are identical to 
the components g x ,g 2 of A's public key (analogously to the ElGamal system parameters 
described above). Also, it is assumed that the random number r' is the same as r. Under 

20 these two assumptions, elements u[,u 2 of ZTs ciphertext message are the same as 
elements u x ,u 2 of A*s ciphertext message. 

Referring now to Figure 14, the system is set up by choosing G as a group of 
prime order q, where q is large (step 1410). Then, as above, key is generated as follows. 
First, random elements g x ,g 2 eG are chosen (step 1412), and random elements 

25 ^p^ 2 '3 ; ii'> ; i2»> ; 2i'> ; 22'>'3i'y32'^ G ^ chosen (step 1414). Next, the group elements 
c = 8\ Si 2 . d x = g x yu g y 2 n , d 2 = gl lx g y * , </ 3 = gp l g y 2 n , and h = g{ are computed (step 
1416). The public key is then calculated to be (g XJ g 2 ,c,d x ,d 2 ,d 3J h) (step 1418) and the 
private key is calculated to be ( *, , x 2 , y x x , y l2 , y 2X , y 22 , y 31 , y n , z) (step 1420). 
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Given a message me G, the encryption method begins by choosing re Z q at 

random (step 1422). Then the ciphertext (w p w 2 ,e,v) is calculated as follows (step 1424): 

u x = g r { , u 2 = g[ , e = ft r m , and v = c r d? r d u fd € 3 r . 

If fi's private key is available for generating the transfer key n, that key is 
5 obtained (step 1426) and then n can be calculated (step 1428) as follows: 

x = (£,0,8 l ,8 2 ,8 3 ) 

where 

e = e'/e = g ( { z '- z)r =uf~ z 

S x =d[ r ld[=u("- y "u(»- y » 
S 2 =d' 2 r /d r 2 =uf»- y »u^- y " 
8 x =d'» Id" =u y '" £ - y »u^ £ - y * 

The ciphertext transformation is then 

10 u[ = u x , u 2 - w 2 , e = ee , and v' = v68 x l 8 2 2 8$ . 

This transforms the ciphertext (u x ,u 2 ,e,v) into (a p ii 2 ,e',v') (step 1430). 

The recipient/delegatee is then able to decrypt the transformed cyphertext 
(u XJ u 2 ,e\v). As above, the decryption algorithm first tests if 
v ' = ^^^34.^1^^^1342^ (step 1432 ). If not, the decryption effort is rejected 

15 (step 1434). Otherwise, the message m is calculated as m = e lu[ z (step 1436). 

In the case where only the public key of the delegatee B can be used for 
delegating the right to decrypt the message from the delegator A to B, one needs to save 
and use the random number r used initially in encrypting the message for A. This may be 
a problem where the party to generate the transfer key is not A, and may not be a problem 

20 if the party is, in fact, A. In any case, if it is available, the transfer key n can be generated 
using ZTs public key as follows: 

x = (£,0,8 x ,8 2 ,8 3 ) 
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where 

e = e'le = {gflglY={h'lhY 
0 = c r lc r = (c7c)' 

S x — d[ r I d[ — (d[l d x Y 
S 2 = d 2 / d 2 = (d 2 I d 2 Y 
S x = d'* I d* = (d^ £ I d 3 ) r 

The proxy transformation is then 

u[ = w, , u 2 = u 2 , e ' = ee , and v' = v^J" 1 J 2 " 2 SI . 

5 It is straightforward to verify, in either case, that the delegatee B can use his own 

private key to decrypt the ciphertext (u' } ,u' 2 ,e\v') transformed by the methods set forth 
above. Since the mechanisms used herein on the Cramer-Shoup cryptosystem are the 
same as those used above on ElGamal-like cryptosystems, they are public and non- 
commutative, assuming the Diffie-Hellman problem and the discrete logarithm problem 

10 are difficult to solve. 

As described above, through enhancing common public-key encryption schemes 
with the proxy encryption capability, it becomes possible to support flexible designated 
decryption. This disclosure has presented two public and non-commutative proxy 
encryption schemes, which have inherited the merits of the existing schemes and 

15 discarded their shortcomings. The new schemes have been shown to have direct 
applications to massive document distribution and file protection. The basic idea of these 
new schemes has also been applied to cryptosystems of other types such as the Cramer- 
Shoup cryptosystem, enhancing them into proxy encryption schemes. 

While the various aspects of the present invention have been described with 

20 reference to several aspects and their embodiments, those embodiments are offered by 
way of example, not by way of limitation. The foregoing detailed description of the 
invention has been presented for purposes of illustration and description. It is not 
intended to be exhaustive or to limit the invention to the precise form disclosed, and 
obviously many modifications and variations are possible in light of the above teaching. 

25 The described embodiments were chosen in order to best explain the principles of the 
invention and its practical applications to thereby enable others skilled in the art to best 
utilize the invention in various embodiments and with various modifications as are suited 
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to the particular use contemplated. Those skilled in the art will be enabled by this 
disclosure will be enabled by this disclosure to make various obvious additions or 
modifications to the embodiments described herein; those additions and modifications are 
deemed to lie within the scope of the present invention. It is intended that the scope of 
the invention be defined by the claims appended hereto. 
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